Managing your Discord bot token and secrets safely
Managing your Discord bot token and secrets safely
Your bot token is equivalent to a password for your bot's account โ anyone who has it can control your bot completely, including in servers it's already joined.
Use environment variables
Read the token via process.env.DISCORD_TOKEN (Node.js) or os.environ["DISCORD_TOKEN"] (Python) instead of writing it directly into a source file. Set it from Startup's environment variables rather than hardcoding it, especially if your code is ever pushed to a public repository โ a token committed to git history stays recoverable even after you delete it in a later commit.
If your token leaks
Go to the Discord Developer Portal, open your application, and reset the token under Bot. The old token stops working immediately; update the new one in your server's environment configuration and restart.
Other secrets
API keys for external services (databases, trading/exchange APIs, payment webhooks) your bot uses deserve the same treatment โ environment variables, never hardcoded, never committed to a public repo.
Related: Deploy a Discord bot.
Was this not what you needed?
Tell us what you're trying to do and our team will help directly.
Open a support ticket Ask on Discord